Operate

Production deployment

A checklist for going live.

Checklist#

  • Use the production environment's client ID and API key, and set AUTH_API_URL.
  • Keep AUTH_API_KEY and any whsec_… secret in your host's secret store, never in a NEXT_PUBLIC_ variable.
  • Register your production callback URL (HTTPS) as a redirect URI, and remove any you no longer use.
  • Choose session and access-token lifetimes, and the MFA mode, for the production environment.
  • Set branding and, if you use one, verify your custom domain.
  • Add webhook endpoints and watch for dead deliveries.
  • Sign in, sign out and reset a password once end to end before announcing it.

What fails closed#

  • No AUTH_API_URL in production: the SDK throws on the first request instead of authenticating against the development API.
  • No client ID: the middleware refuses protected routes with 500 and says why, instead of looping through sign-in.
  • Signing keys unreachable: sessions are treated as invalid, never trusted without a check.
  • Cloudflare unreachable: checked submissions on the hosted pages are refused.